Skip to content

Application password

An application password lets a program reach a WordPress site as one user, through the REST API or XML-RPC, without that user's main password. It does not work on the login screen. Each one is made and revoked on the user's profile, and the feature needs HTTPS.

By
WP Ministry
Published

In short

  • An application password is for a program, not a person. It works for the REST API and XML-RPC, and not on the login screen.
  • The program acts as the user the password belongs to. One on an administrator's account is an administrator's access.
  • A password reset does not remove one, and neither do new security keys. Revoke it on the user's profile.

An application password is a password WordPress makes for a program to use. It belongs to one user account. A phone app, a script or a management tool that holds it can act as that user through the REST API or XML-RPC, without ever being given the account's main password. WordPress has had them since version 5.6.

Three things set it apart from the main password:

  • It does not work on the login screen. wp-login.php refuses it like any wrong password.
  • It is shown once. WordPress stores it hashed and cannot show it again.
  • It is revoked on its own. Removing one leaves the main password and the user's other application passwords as they were.

It is 24 letters and numbers. WordPress shows it in groups of four, and it works with or without the spaces.

Where you meet it

Go to Users, then Profile. For someone else's account, go to Users, then All Users, and edit the user. Near the bottom is a section headed "Application Passwords", which says they "cannot be used for traditional logins to your website."

To make one, type a name into "New Application Password Name" and press "Add Application Password". WordPress answers "Your new password for" with the name, and "Be sure to save this in a safe location. You will not be able to retrieve it."

Below is a table of the ones that exist, with the columns "Name", "Created", "Last Used" and "Last IP", and a "Revoke" button on each row. "Revoke all application passwords" removes the lot. "Last Used" is accurate to within 24 hours.

A tool may instead send you to a screen in your own dashboard titled "Authorize Application". Pressing "Yes, I approve of this connection" there makes an application password for it.

What goes wrong

  • The section says "The application password feature requires HTTPS, which is not enabled on this site." By default the feature is available only on a site served over HTTPS. Installing a free SSL certificate covers the move. If the site is on HTTPS and the section is missing, a security plugin or custom code has switched the feature off.
  • One nobody remembers still works. A password made for an old script or a former developer's tool keeps working until it is revoked. Resetting the account's password does not remove it. Run through them when you take a site over, as in the client site takeover checklist, and when a partner's access ends, as in the guide to outsourcing maintenance.
  • It is left behind after a break-in. Anyone logged in as a user can add one to that account, and an administrator can add one to any account. Changed passwords and new security keys leave it in place. Dealing with an unknown admin user and why a site keeps getting hacked both include the check.
  • A second login step does not cover it. Two-factor authentication protects the login screen. A program has no screen to type a code into, so it uses an application password and is asked for no code.

How to look at yours

With WP-CLI, list one user's application passwords, with the user's ID in place of 1:

bash
wp user application-password list 1 --fields=name,created,last_used,last_ip

created and last_used are printed as Unix timestamps, such as 1791427978. An empty last_used means it has never been used.

Common questions

Can someone log in to my dashboard with an application password?

No. The login screen refuses it. That does not make it harmless: a program that holds one acts as that user, with that user's role. Treat one on an administrator's account like the administrator's password.

Can I switch application passwords off?

Yes. WordPress has a filter for it, wp_is_application_passwords_available, and some security plugins use it. Check first that nothing connects to the site with one: the "Last Used" column shows which are in use.

Not sure what is wrong?

Tell us what you see. We reply with the cause and a fixed quote, and the diagnosis is free.